# security headers adapted from https://www.digitalocean.com/community/tools/nginx
add_header X-XSS-Protection          "1; mode=block" always;
add_header X-Content-Type-Options    "nosniff" always;
add_header Referrer-Policy           "same-site" always;
add_header Content-Security-Policy   {{ openwisp2_nginx_csp }}
add_header Permissions-Policy        "interest-cohort=()" always;
add_header Strict-Transport-Security "max-age=31536000" always;
